Also known as: UNC757, Parisite, Pioneer Kitten, RUBIDIUM, Lemon Sandstorm
Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.(Citation: ClearkSky Fox Kitten February 2020)(Citation: CrowdStrike PIONEER KITTEN August 2020)(Citation: Dragos PARISITE )(Citation: ClearSky Pay2Kitten December 2020)
Executive Summary
Fox Kitten (aka UNC757, Parisite, Pioneer Kitten, RUBIDIUM, Lemon Sandstorm) is a suspected state-sponsored cyber threat group with links to the Iranian government. Active since at least 2017, Fox Kitten has targeted multiple sectors globally, including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering. The group employs advanced persistent threat (APT) tactics, often leveraging known malware tools such as SystemBC, China Chopper, and Pay2Key, to infiltrate networks and exfiltrate sensitive data.
Goals & Targeting
Fox Kitten’s targeting strategy focuses on sectors with critical infrastructure and sensitive data, such as oil and gas, defense, healthcare, and technology. The group likely aims to gather intelligence for strategic advantage, possibly in support of national interests or geopolitical objectives. Its global targeting suggests a focus on maximizing access to diverse industries and regions, potentially to build a repository of sensitive information.
Enhanced Description
Fox Kitten is a cyber threat actor with suspected ties to the Iranian government, first observed since at least 2017. The group has demonstrated significant operational persistence, targeting organizations across various industries—oil and gas, technology, government, defense, healthcare, manufacturing, and engineering—in regions including the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten's activities suggest a high level of sophistication, utilizing a combination of malware tools such as SystemBC, China Chopper, and Pay2Key, along with advanced tactics to compromise victim networks. The group’s primary motivation appears to be cyber-espionage and data exfiltration, though specific strategic goals remain unclear in available intelligence. Fox Kitten's use of TTPs including remote services exploitation, credential dumping via LSASS memory, and persistence mechanisms highlights its ability to quietly infiltrate targets and maintain long-term access.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Fox Kitten’s campaigns typically involve long-term infiltration and data exfiltration. The group has been linked to multiple attacks across sectors, with specific patterns including the use of web shells for persistence and credential dumping via LSASS memory. While no specific high-profile campaign names are publicly documented, Fox Kitten's operational tempo suggests a steady activity level targeting diverse industries globally.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Fox Kitten's existence and APT activities, particularly regarding its suspected Iranian government nexus. However, specific details about primary motivation, long-term goals beyond data collection, and exact toolset capabilities remain unclear. Additional intelligence on campaign specifics could enhance understanding of this group’s operational methods.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
41
Techniques
3
Tools
0
Campaigns
0
IOCs
0
Observed Data
11
Tactics